2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14273 | MEDIUM | 5.3 | 1.1% | Sep 26, 2019 | In SilverStripe assets 4.0, there is broken access control on files. |
| CVE-2019-14272 | MEDIUM | 5.4 | 0.7% | Sep 26, 2019 | In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS. |
| CVE-2019-16903 | MEDIUM | 5.3 | 1.9% | Sep 26, 2019 | Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should b... |
| CVE-2019-16738 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup... |
| CVE-2019-16892 | MEDIUM | 5.5 | 1.6% | Sep 25, 2019 | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the unco... |
| CVE-2019-16890 | MEDIUM | 5.4 | 0.7% | Sep 25, 2019 | Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments. |
| CVE-2019-12709 | MEDIUM | 6.7 | 0.5% | Sep 25, 2019 | A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 900... |
| CVE-2019-12672 | MEDIUM | 6.8 | 0.6% | Sep 25, 2019 | A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical ac... |
| CVE-2019-12670 | MEDIUM | 6.7 | 0.3% | Sep 25, 2019 | A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G... |
| CVE-2019-12668 | MEDIUM | 4.8 | 0.8% | Sep 25, 2019 | A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote at... |
| CVE-2019-12667 | MEDIUM | 4.8 | 0.8% | Sep 25, 2019 | A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to cond... |
| CVE-2019-12666 | MEDIUM | 6.7 | 1.1% | Sep 25, 2019 | A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform dire... |
| CVE-2019-12662 | MEDIUM | 6.7 | 0.3% | Sep 25, 2019 | A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali... |
| CVE-2019-12661 | MEDIUM | 6.7 | 0.4% | Sep 25, 2019 | A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authentic... |
| CVE-2019-12660 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the ... |
| CVE-2019-4571 | MEDIUM | 5.4 | 0.7% | Sep 25, 2019 | IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2019-12649 | MEDIUM | 6.7 | 0.2% | Sep 25, 2019 | A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker ... |
| CVE-2019-6655 | MEDIUM | 5.3 | 1.1% | Sep 25, 2019 | On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PE... |
| CVE-2019-6654 | MEDIUM | 4.3 | 0.5% | Sep 25, 2019 | On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian A... |
| CVE-2019-12245 | MEDIUM | 5.3 | 1.4% | Sep 25, 2019 | SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta... |
| CVE-2019-12205 | MEDIUM | 6.1 | 0.9% | Sep 25, 2019 | SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS. |
| CVE-2019-12203 | MEDIUM | 6.3 | 0.4% | Sep 25, 2019 | SilverStripe through 4.3.3 allows session fixation in the "change password" form. |
| CVE-2019-6653 | MEDIUM | 5.4 | 0.6% | Sep 25, 2019 | There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 syst... |
| CVE-2019-6652 | MEDIUM | 6.5 | 0.6% | Sep 25, 2019 | In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Laye... |
| CVE-2019-6651 | MEDIUM | 5.3 | 1.1% | Sep 25, 2019 | In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now